Blog
CVE-2026-83548 (CVSS 10.0) + CVE-2026-83549: SonicWall SMA 1000 Zero-Day Chain Enables Pre-Auth RCE — Patch Immediately
SonicWall confirms active exploitation of two SMA 1000 zero-days: CVSS 10.0 SSRF (CVE-2026-83548) chained with command injection (CVE-2026-83549) for pre-auth RCE on models 6210, 7210, 8200v.
Read More →CVE-2026-62911 (CVSS 8.1): 22,000 Exchange Servers Exposed as Pwn2Own RCE Chain Goes Public — Every Mailbox at Risk
CVE-2026-62911 lets unauthenticated attackers relay NTLM to Exchange MRSProxy and seize every mailbox. 21,899 servers remain unpatched. Apply SU9 (KB5121573) and enable EPA now.
Read More →CVE-2026-82329 (CVSS 9.8): Attackers Mint Admin Tokens in JFrog Artifactory Days After Disclosure — Your Software Supply Chain Is at Risk
CVE-2026-82329 (CVSS 9.8) lets unauthenticated attackers mint JFrog Artifactory admin tokens. Active exploitation confirmed Sept 1, 2026. Patch now or restrict access.
Read More →CVE-2026-0768 & CVE-2026-66066: AI Workflow and Rails Servers Under Active Attack — 360+ Intrusions Detected, Cloud Keys at Risk
Attackers exploit CVE-2026-0768 (CVSS 9.8) in Langflow and CVE-2026-66066 (CVSS 9.5) in Ruby on Rails, harvesting OpenAI, AWS credentials in a live 360+ intrusion campaign.
Read More →Fire Ant: China-Nexus APT Hijacks Cisco IOS XR Routers and TACACS+ Servers to Spy on Critical Networks
China-linked Fire Ant (UNC3886) plants TacTap credential-harvester on TACACS+ servers and BridgeAgent backdoor on Linux management hosts, turning Cisco IOS XR routers into espionage platforms.
Read More →CVE-2026-12569 (CVSS 9.3): Cl0p’s Custom Web Shell Is Draining Engineering Blueprints from 40+ Global Manufacturers
Cl0p ransomware's custom JSP web shell exploits CVE-2026-12569 (CVSS 9.3) to silently drain engineering data from PTC Windchill and FlexPLM — 40+ victims named including Shell, Philips, and GE. Patch…
Read More →CVE-2026-33824 (CVSS 9.8): Chinese APT Uses DeepSeek AI to Autonomously Attack 460+ Windows IKE VPN Endpoints — CISA KEV Patch Deadline Passed
A Chinese-speaking threat actor used DeepSeek AI and the Hermes Agent framework to autonomously exploit CVE-2026-33824, a CVSS 9.8 pre-auth RCE in Windows IKE. Over 460 targets hit; CISA KEV…
Read More →CVE-2026-8452 (CVSS 9.8): Citrix NetScaler’s “DoS-Only” Patch Is Pre-Auth Root RCE — CISA Deadline Passed, Webshells Deployed on 22,000+ Exposed Appliances
CVE-2026-8452 (CVSS 9.8) in Citrix NetScaler enables pre-auth root RCE via heap buffer overflow. CISA’s federal deadline passed Aug 29—patch to 14.1-73.32+ or 13.1-63.21+ immediately.
Read More →CVE-2026-68820 (CVSS 7.0): Lazarus Group’s Operation Dream Job Plants Kernel Rootkit in Indian Defence Firms
Lazarus Group exploited Windows zero-day CVE-2026-68820 (CVSS 7.0) via fake job offers, deploying FudModule 3.1 rootkit in Indian defence firms. Patch now.
Read More →CVE-2026-73570 (CVSS 8.9): Zimbra Mail Servers Under Mass Attack — 274 Servers Compromised as CISA Issues Emergency Patch Deadline
CVE-2026-73570 is an unauthenticated RCE in Zimbra’s SNMP monitoring component, actively exploited in the wild. 274 servers compromised in days. CISA added to KEV August 21. Patch ZCS 10.1.20 now.
Read More →